SBOM
Your supply chain, on the same thread.
Import CycloneDX or SPDX and every component becomes a first-class item — linked to the risks it threatens and the tests that cover it, with CVE and CVSS tracking and suspect propagation when a new vulnerability lands. The supply chain joins the same connected record as everything else.
Components as first-class items — with CVE / CVSS tracking, license policy, and suspect propagation when a new vulnerability is disclosed.
What it does
The supply chain, no longer a document apart.
An SBOM is usually filed away and consulted only when a vulnerability makes the news. Here it is on the thread — traceable, governed, and live.
CycloneDX & SPDX import
Import a standard SBOM and every component becomes a first-class item in the same connected record as your requirements, tests, and risks.
CVE & CVSS tracking
Each component carries its vulnerability information, so the security posture of your supply chain is visible in context — and tied to what depends on it.
License policy & attestation
The same governance extends to the legal dimension of the supply chain, with license policies and attestation.
Suspect propagation
When a new CVE lands, suspect status propagates to the items that depend on the affected component — turning a supply-chain event into a specific, actionable list.
On the thread
A new CVE becomes a list, not a hunt.
Because components are linked into the thread, a disclosed vulnerability points straight at what to re-examine — FDA-cybersecurity-relevant capability, built in.
A component inventory can be proposed from the model, then completed by a human.
A component vulnerability propagates suspect status to the risks that depend on it.
Components link to the verification that covers them, so security posture ties back to evidence.
Derive with AI
Derive a component inventory from your model.
The governed derivation engine proposes an SBOM component inventory from your architecture — it builds the structure and cites its sources, but it will not fabricate versions, hashes, suppliers, or licenses. You supply those facts and accept.
Govern your supply chain like everything else.
Bring your SBOM onto the thread — tracked, traced, and ready to react the moment a new vulnerability is disclosed.